Endpoint Detection and Response security agents rely heavily on kernel-mode drivers to observe system state changes before user-mode code can alter evidence. By registering executive callbacks via routines like PspCreateProcessNotifyRoutine, security drivers receive execution context whenever a process or thread initializes. Understanding how these callbacks operate at the kernel structure level is essential for both defense engineering and offensive telemetry assessment.
Registration Routines and Callback Array Structure
The Windows kernel maintains an array of pointers pointing to registered callback routines for key system events. When a security driver calls PsSetCreateProcessNotifyRoutineEx, the kernel allocates an EX_CALLBACK_ROUTINE_BLOCK structure and appends its reference to the internal notification array. Because these arrays sit in protected kernel memory, reversing their layout requires examining system structures directly within a local kernel debugging session.
Inspecting the EX_CALLBACK_ROUTINE_BLOCK reveals that the actual function pointer is bitwise encoded alongside function attributes. Security analysts must strip the lower bits of the pointer value to resolve the actual virtual address of the driver handling the callback routine.
Execution Flow and Telemetry Generation
When a process creation request reaches NtCreateUserProcess, the kernel executes the routine array before the initial thread starts instruction fetching in user space. The callback receives a PS_CREATE_NOTIFY_INFO structure detailing file image paths, command-line parameters, parent process IDs, and creation flags. This early intercept point allows security drivers to inspect the process arguments or terminate execution before malformed payloads execute.
Inspecting Kernel Callbacks via Debugging Tools
To list active process creation callbacks during system analysis, WinDbg provides kernel symbols that directly expose the notify routine arrays. Commands such as evaluating the symbol PspCreateProcessNotifyRoutine reveal driver function pointers across loaded modules. Identifying unauthorized or modified entries within this callback array serves as a primary indicator of kernel-level rootkit interference or driver tampering.